Acer Spin 5 (SP513-52N) with Windows 10 22H2/11 23H2 can't connect to 802.1x Wi-Fi, errors with TLS/EAP-TLS authentication

Mcintyre, Craig 5 Reputation points
2024-11-25T15:42:05.5533333+00:00

Hello!

I've been testing with Certificate Wi-Fi in our environment using EAP-TLS, however I'm running into a peculiar issue where only the Acer Spin 5, model SP513-52N will not connect to the network. It has the same certificates and configuration as other models in our fleet (Lenovos, Dell, etc.) and they all connect just fine, but the Spin 5s in particular will not.

Some details, this is an WPA2-Enterprise network using device certificates issued from our on-prem Ruckus CloudPath server. I receive a "Can't connect to this network." error. In the RADIUS logs, I get entries such as: "ERROR: (TLS) TLS - Alert read:fatal:access denied"

"eap_tls ERROR: (TLS) Failed reading from OpenSSL:…"

"ERROR: (TLS) Cannot continue, as the peer is misbehaving."

"ERROR: … EAP sub-module failed. Sending EAP Failure (code 4)"

I also threw this over in the Acer support forums since it's device-specific in our environment, but also wanted to post here just in case there are some general other troubleshooting steps that I've missed or overlooked that anyone can think of. So far, I've just done usual troubleshooting in terms of running any and all updates (both Win 10 and Win 11) for OS and Drivers, and even swapped out the Wi-Fi card for known working ones from other devices, renewing the certificate each time before trying to connect.

Any help would be appreciated. Thank you!

Windows for business | Windows Client for IT Pros | Networking | Network connectivity and file sharing
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Mcintyre, Craig 5 Reputation points
    2024-11-27T15:33:03.1333333+00:00

    Solution: It turned out to be a bug in our version of Ruckus Cloudpath ES (6.0.5816) that they have identified and addressed in the next release of the software. It has to do with RSA-PSS signature and the TPM.

    I was able to get this device working from a workaround detailed here.

    Prior to this discovery, we had confirmed all of the above steps listed and tried different Wi-Fi cards.

    Thank you!

    0 comments No comments

  2. Jing Zhou 7,800 Reputation points Microsoft External Staff
    2024-11-26T23:48:17.85+00:00

    Hello,

     

    Thank you for posting in Q&A forum.

    To further troubleshoot this issue, please kindly try below steps:

    1.Ensure that the correct certificates are properly installed and trusted on the device in adapter properties.

    2.Check if the EAP-TLS authentication method is configured on RADIUS server.

    3.Ensure that the server certificate is trusted by the client.

    4.Capture the network trace by network monitor or wireshark and check if there's any insight in the trace.

     

    I hope the information above is helpful.

    If you have any questions or concerns, please feel free to let us know.

     

    Best regards,

    Jill Zhou

     


    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.